Wazuh logo

Wazuh

Open source XDR and SIEM platform for endpoint, cloud, and container security

Open Source Alternative to
Repository activity
  • Stars15.9k
  • Forks2.3k
  • Open Issues2.9k
wazuh health score - Linux Foundation Insights
License

Other

Languages
  • C++
  • C
  • Python
Wazuh screenshot

About Wazuh

Wazuh is a free and open source platform for threat prevention, detection, and response. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments, with an endpoint security agent and a management server that collects and analyzes agent data.

It scans for malware, rootkits, suspicious anomalies, vulnerabilities, and configuration issues. Agents forward operating system and application logs for rule-based analysis, file integrity monitoring tracks content and permission changes, and active response can block threats or run remote commands. The web interface provides data visualization, analysis, status, and management.

Wazuh integrates with the Elastic Stack for alert navigation and includes orchestration for Docker, Ansible, Chef, Puppet, Kubernetes, Bosh, and Salt. It is maintained by Wazuh Inc., based on OSSEC, and offers self-hosted deployment with Docker containers and installation guides.

Key features

  • Endpoint agents and central manager
  • Log analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection from CVE data
  • Active response and remote commands

Details

First released
2015
Platforms
Windows · macOS · Linux
Self-hosting
Self-hostable
Deployment
Docker
Security
Threat prevention, detection, response
Governance
Wazuh Inc., based on OSSEC